SonicWall SSLVPN Vulnerability
SonicWall has revealed a critical security flaw in its SSLVPN service that could allow unauthenticated remote attackers to crash vulnerable firewall appliances, potentially leading to major disruptions across enterprise networks.
The flaw, identified as CVE-2025-32818, carries a high severity rating with a CVSS score of 7.5 and impacts several SonicWall firewall models running certain firmware versions.
Security researchers discovered that the issue stems from a NULL Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual Office interface.
This vulnerability enables remote attackers to crash targeted firewall appliances without any need for authentication, resulting in a Denial-of-Service (DoS) condition that can severely disrupt critical network operations.
“When exploited, the flaw causes the device to reference a NULL pointer, leading to a crash and forced restart of the firewall,” explained Jon Williams of Bishop Fox, who is credited with discovering the issue.
“Because the attack requires no authentication, it poses a serious threat to any SonicWall device exposed to the internet.”
The vulnerability is classified under CWE-476 (NULL Pointer Dereference) and, according to the CVSS:3.0 scoring vector, is network-accessible, low in complexity, requires no privileges or user interaction, and predominantly affects system availability.
Risk Factors and Details
- Affected Products:
– Gen7 NSv (NSv 270, 470, 870)
– Gen7 Firewalls (TZ270, TZ370, TZ470, TZ570, TZ670 series; NSa 2700, 3700, 4700, 5700, 6700; NSsp 10700, 11700, 13700, 15700)
– TZ80 (firmware version ≤ 8.0.0-8037) - Impact:
Denial-of-Service (DoS) through firewall crash - Exploit Prerequisites:
– Network access to the vulnerable SSLVPN interface
– No authentication required - CVSS 3.1 Score:
7.5 (High)
Affected Products
The vulnerability specifically affects SonicWall Gen7 NSv models (NSv 270, NSv 470, NSv 870) and Gen7 Firewalls, including the TZ series (TZ270, TZ270W, TZ370, TZ370W, TZ470, TZ470W, TZ570, TZ570W, TZ570P, TZ670), the NSa series (NSa 2700, 3700, 4700, 5700, 6700), and the NSsp series (NSsp 10700, 11700, 13700, 15700) running firmware versions between 7.1.1-7040 and 7.1.3-7015.
In addition, the TZ80 model running firmware version 8.0.0-8037 or earlier is also impacted.
It is important to note that SonicOS GEN6 and GEN7 7.0.x firmware versions are not vulnerable to this exploit.
Remediation
SonicWall has released patched firmware versions to address the vulnerability. Affected customers are strongly urged to upgrade to:
- Firmware version 7.2.0-7015 or higher for Gen7 devices
- Firmware version 8.0.1-8017 or higher for TZ80 models
According to SonicWall’s security advisory, no workaround is available—making firmware updates the only effective mitigation.
Recommendations
Security experts recommend that organizations immediately apply the patches, especially for internet-facing firewalls.
Additionally, organizations should closely monitor their devices for signs of potential exploitation, such as unexpected reboots or service disruptions.




